Weaknesses of type CWE-287

2,454 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%CVE-2022-46316CRITICALA thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integritEPSS 0.5%CVE-2026-55761HIGHPortainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer InstancesEPSS 0.5%CVE-2026-21881CRITICALKanboard is Vulnerable to Reverse Proxy Authentication BypassEPSS 0.5%CVE-2025-5247MEDIUMGowabby HFish url.go LoadUrl improper authenticationEPSS 0.5%CVE-2022-23501MEDIUMTYPO3 vulnerable to Improper Authentication in Frontend LoginEPSS 0.5%CVE-2022-39238MEDIUMImproper Authentication in Arvados when using PAM as identity providerEPSS 0.5%CVE-2025-66698HIGHAn issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.EPSS 0.5%CVE-2025-2344MEDIUMIROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authenticationEPSS 0.5%CVE-2026-94606HIGHauthentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStageEPSS 0.5%CVE-2026-24038HIGHHorilla HR has 2FA Bypass through its OTP Handling LogicEPSS 0.5%CVE-2026-46715MEDIUMFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptanceEPSS 0.5%CVE-2025-57434HIGHCreacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants accesEPSS 0.5%CVE-2022-47209HIGHA support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “suppEPSS 0.5%CVE-2023-28963MEDIUMJunos OS: User-controlled input vulnerability in J-WebEPSS 0.5%CVE-2025-52553MEDIUMauthentik has Insufficient Session verification for Remote Access Control endpoint accessEPSS 0.5%CVE-2025-49146HIGHpgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require ConfigurationEPSS 0.5%CVE-2026-7844MEDIUMchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authenticationEPSS 0.5%CVE-2024-25106CRITICALOpenObserve Unauthorized Access Vulnerability in Users APIEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%